Export limit exceeded: 10546 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10546 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-26526 1 Moodle 1 Moodle 2025-08-08 6.5 Medium
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
CVE-2025-0765 1 Gitlab 1 Gitlab 2025-08-08 4.3 Medium
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.
CVE-2024-12244 1 Gitlab 1 Gitlab 2025-08-08 4.3 Medium
An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
CVE-2025-0652 1 Gitlab 1 Gitlab 2025-08-08 4.3 Medium
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.
CVE-2024-31409 1 Cyberpower 2 Powerpanel, Powerpanel Business 2025-08-07 6.5 Medium
Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
CVE-2025-43720 1 H-mdm 1 Headwind Mdm 2025-08-07 6.5 Medium
Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.
CVE-2025-43977 1 Sktelecom 1 Com.skt.prod.dialer 2025-08-07 4.3 Medium
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.
CVE-2025-43976 1 Textnow 1 2ndline 2025-08-07 4.3 Medium
The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.
CVE-2025-26531 1 Moodle 1 Moodle 2025-08-07 3.1 Low
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
CVE-2025-26532 1 Moodle 1 Moodle 2025-08-06 3.1 Low
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
CVE-2025-0781 2 Debian, Flightgear 2 Debian Linux, Simgear 2025-08-06 8.6 High
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
CVE-2024-3976 1 Gitlab 1 Gitlab 2025-08-06 6.5 Medium
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.
CVE-2024-1539 1 Gitlab 1 Gitlab 2025-08-06 4.3 Medium
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.
CVE-2025-0516 1 Gitlab 1 Gitlab 2025-08-06 4.3 Medium
Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.
CVE-2024-7296 1 Gitlab 1 Gitlab 2025-08-06 2.7 Low
An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.
CVE-2025-2045 1 Gitlab 1 Gitlab 2025-08-06 4.3 Medium
Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.
CVE-2025-1540 1 Gitlab 1 Gitlab 2025-08-06 3.1 Low
An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."
CVE-2024-23823 1 Vantage6 1 Vantage6 2025-08-06 4.2 Medium
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server. The impact is limited because v6 does not use session cookies. This issue has been addressed in commit `70bb4e1d8` and is expected to ship in subsequent releases. Users are advised to upgrade as soon as a new release is available. There are no known workarounds for this vulnerability.
CVE-2025-8335 1 Code-projects 1 Simple Car Rental System 2025-08-05 4.3 Medium
A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-8434 2 Anisha, Code Projects 2 Online Movie Streaming, Online Movie Streaming 2025-08-05 7.3 High
A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the file /admin.php. The manipulation of the argument ID leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.